13-step checklist when a breach or major cyber incident occurs:
- Assess the situation
- Call cyber insurer if applicable
- Assemble crisis team
- Immediate containment — preserve evidence
- Check NCSC reporting (~24h) under NIS2/Cbw
- Report to Dutch DPA within 72h if required
- Inform data subjects if high risk
- Consider alternative suppliers if needed
- Report to police if cybercrime
- Update DPA/NCSC filings on time
- Record in internal breach register
- Assess damage recovery options
- Prevent recurrence — root cause and review